mirror of
https://github.com/0xMarcio/cve.git
synced 2025-12-16 20:27:21 +00:00
1.3 KiB
1.3 KiB
CVE-2010-0928
Description
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."
POC
Reference
- http://www.eecs.umich.edu/%7Evaleria/research/publications/DATE10RSA.pdf
- http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/
Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/GrigGM/05-virt-04-docker-hw
- https://github.com/PajakAlexandre/wik-dps-tp02
- https://github.com/cdupuis/image-api
- https://github.com/chnzzh/OpenSSL-CVE-lib
- https://github.com/fokypoky/places-list
- https://github.com/garethr/findcve
- https://github.com/garethr/snykout
- https://github.com/jasona7/ChatCVE